Closed

Tools for compliance with CRA requirements and obligations

DIGITAL JU SME Support Actions

Basic Information

Identifier
DIGITAL-ECCC-2024-DEPLOY-CYBER-06-COMPLIANCECRA
Programme
Deployment Actions in the area of Cybersecurity
Programme Period
2021 - 2027
Status
Closed (31094503)
Opening Date
January 16, 2024
Deadline
March 26, 2024
Deadline Model
single-stage
Budget
€22,250,000
Min Grant Amount
0
Max Grant Amount
0
Expected Number of Grants
0
Keywords
DIGITAL-ECCC-2024-DEPLOY-CYBER-06-COMPLIANCECRADIGITAL-ECCC-2024-DEPLOY-CYBER-06CybersecurityCybersecurity DomainsOpen Source SoftwareStandards

Description

Expected Outcome:

Deliverables:

  • Tools to simplify and automate CRA compliance, with particular focus towards automated compliance tools that would ensure alignment with the CRA cybersecurity essential requirements.
  • Tools to simplify and automate CRA compliance documentation obligations.
Objective:

The objective of this topic is to support the implementation of the proposed Cyber Resilience Act (CRA) through tools that support, and where possible automate, internal compliance procedures, including testing and specification drafting with focus towards European SMEs, in particular micro and small enterprises.

Scope:

This action aims at the design and development of tools to facilitate, and where possible automate, CRA compliance, with particular focus towards automated compliance tools that would ensure alignment with the CRA cybersecurity essential requirements and documentation obligations.

CRA compliance solutions are foreseen based on technical specifications, training modules, and other relevant material. Tools for penetration testing, testing facilities and other cybersecurity practices, aligning with CRA requirements, are also in the scope.

Tools should be tailored towards needs of European SMEs, with a focus on micro and small enterprises, though also usable by broader stakeholder categories, such as:

  • Manufacturers of relevant product categories falling within the scope of the CRA, including software developers.
  • Others, such as distributors, importers, open-source community, etc.

CRA compliance tools should be made widely available on fair and reasonable terms and also take into consideration the specific needs of different stakeholders such as the behaviour of consumers, business users, and other relevant factors.

Priority should be given to solutions available to use free of charge or free and open-source software (FOSS) solutions.

These activities should be carried out in close coordination and, where possible collaboration, with the Network of National Coordination Centres (NCCs), the European Digital Innovation Hubs (EDIHs) network, the EU Cybersecurity Skills Academy, other relevant European and National cybersecurity entities, and other projects of this work programme.

This action aims at the creation of tools that, amongst others, do penetration testing or document technical specifications with relation to cybersecurity, including for entities that are providers of essential services and critical infrastructures. As such tools and information could be exploited by malicious actors, they must be protected against possible dependencies and vulnerabilities in cybersecurity to pre-empt foreign influence and control. As previously noted, participation of non-EU entities entails the risk of highly sensitive information about security infrastructure, risks and incidents being subject to legislation or pressure that obliges those non-EU entities to disclose this information to non-EU governments, with an unpredictable security risk. Therefore, based on the outlined security reasons, the actions relating to these technologies are subject to Article 12(5) of Regulation (EU) 2021/694.

Eligibility & Conditions

Conditions

Conditions



1. Admissibility conditions: described in section 5 of the call document 

Proposal page limits and layout: described in Part B of the Application Form available in the Submission System

2. Eligible countries: described in section 6 of of the call document

3. Other eligibility conditions: described in section 6 of the call document

4. Financial and operational capacity and exclusion: described in section 7 of the call document

  • Award criteria, scoring and thresholds: described in section 9 of the call document

  • Indicative timeline for evaluation and grant agreement: described in section 4 of the call document

6. Legal and financial set-up of the grants: described in section 10 of the call document

Documents



Call document is accessible here

Standard application form — call-specific application form is available in the Submission System

Detailed budget table - available in the Submission System

DIGITAL EUROPE PROGRAMME General MGA v1.0

Guidance Classification of information in DIGITAL projects

Guidelines on How to Complete your Ethics Self-Assessment

Guidance on participation in DEP - restricted calls 

Support & Resources

For help related to this call, please contact us here

Funding & Tenders Portal FAQ – Submission of proposals.

IT Helpdesk – Contact the IT helpdesk for questions such as forgotten passwords, access rights and roles, technical aspects of submission of proposals, etc.

Online Manual – Step-by-step online guide through the Portal processes from proposal preparation and submission to reporting on your on-going project. Valid for all 2021-2027 programmes.

Latest Updates

Last Changed: July 17, 2024

For information on the evaluations results of this call we invite you to consult the Flash call info (evaluation results) in the following link.

Last Changed: January 16, 2024
The submission session is now available for: DIGITAL-ECCC-2024-DEPLOY-CYBER-06-STANDARDPQC(DIGITAL-JU-CSA), DIGITAL-ECCC-2024-DEPLOY-CYBER-06-TRANSITIONEUPQC(DIGITAL-JU-CSA), DIGITAL-ECCC-2024-DEPLOY-CYBER-06-ENABLINGTECH(DIGITAL-JU-SIMPLE), DIGITAL-ECCC-2024-DEPLOY-CYBER-06-COMPLIANCECRA(DIGITAL-JU-SME), DIGITAL-ECCC-2024-DEPLOY-CYBER-06-STRENGTHENCRA(DIGITAL-JU-GFS), DIGITAL-ECCC-2024-DEPLOY-CYBER-06-PQCINDUSTRY(DIGITAL-JU-SIMPLE)